top of page

ENTERPRISE INTERNAL CONTROL & STANDARD OPERATING PROCEDURE MANUAL

  • Writer: Nhung Nguyen
    Nhung Nguyen
  • Jun 27
  • 12 min read


Document Code: CO-ICM-2026-V1

Target Compliance Frameworks: COSO 2013, PCAOB AS 2201, SOX Section 404, IFRS / US GAAP

Scope: Global Operations & Subsidiary Frameworks

SECTION I: MANUAL ARCHITECTURE & COMPLIANCE METHODOLOGY

1. The COSO 2013 Control Environment

This manual enforces the five integrated components of the COSO 2013 Internal Control-Integrated Framework:

  • Control Environment: Foundation for all other components, driven by "Tone at the Top," ethical values, and organizational structure.

  • Risk Assessment: Dynamic process for identifying and analyzing risks to achieving objectives.

  • Control Activities: Policies and procedures helping ensure management directives to mitigate risks are carried out.

  • Information & Communication: Identification, capture, and exchange of information in a form and timeframe enabling people to carry out responsibilities.

  • Monitoring Activities: Ongoing evaluations, separate evaluations, or some combination of the two used to ascertain whether each of the five components of internal control is present and functioning.

2. Control Classification Matrix

Every control documented in this manual must be cataloged using four primary dimensional attributes:

     
  • Execution Mode:

    • Automated (A): System-enforced controls (e.g., three-way match tolerances in SAP).

    • Semi-Automated (SA): System-generated report reviewed manually (e.g., reviewing an ERP-generated exception report).

    • Manual (M): Performed completely outside systems (e.g., physical stock counts).

  • Control Objective:

    • Preventative (P): Designed to stop errors or fraud before they occur.

    • Detective (D): Designed to identify and correct errors or fraud after occurrence.

  • Significance:

    • Key Control (KC): Crucial to preventing or detecting material misstatements in financial reports. Tested directly by auditors.

    • Non-Key Control (NK): Enhances operational efficiency or administrative accuracy but is not primary to SOX/financial assertion mitigation.

  • Financial Assertions Addressed:

    • C - Completeness

    • E - Existence / Occurrence

    • A - Accuracy / Valuation

    • R - Rights & Obligations

    • P - Presentation & Disclosure

SECTION II: GRANULAR CORE BUSINESS CYCLES

1. Sales and Cash Collection Cycle (Revenue & Receivables)

1.1 End-to-End Procedural Flow

  1. Lead & Sales Proposal: Opportunities are qualified in CRM. Proposals are created using system-locked price libraries.

  2. MOU & Credit Evaluation: Prior to legal binding, a credit review is initiated via the credit team.

  3. Contract Execution & Master Data Setup: Legal signs off on deviated terms. Customer master data is locked in the ERP.

  4. Order Processing: Sales Order (SO) generated against standard SKUs.

  5. Fulfillment & Delivery: Warehouse picks, packs, and ships. Delivery Order (DO) or Bill of Lading (BOL) is executed.

  6. Billing & Invoice Generation: Revenue accounting issues a fiscal invoice matching actual shipped quantities.

  7. Cash Application & AR Reconciliation: Remittance received via lockbox/wire. Applied to open balances; monthly age-analysis performed.

1.2 Process Flow Diagram

[CRM Proposal] ──> [Credit Evaluation] ──> [Contract Signed] ──> [Sales Order Approved]
                                                                        │
[AR Reconciliation] <── [Cash Receipt] <── [Invoice Issued] <── [Fulfillment & DO]

1.3 Risk & Control Matrix (RCM)

Control ID

Process Step

Risk Description (What Could Go Wrong - WCGW)

Financial Assertion

Control Activity Description

Type / Mode

Owner

Evidence Artifact

REV-KC-01

Credit Review

Orders processed for high-risk customers, causing material uncollectible bad debts.

A

ERP system automatically blocks sales orders if a customer's balance exceeds approved credit limits. Credit limit overrides require written approval from the CFO.

P / A

Credit Manager

System Credit Exception Log & Sign-off

REV-KC-02

Fulfillment

Shipments made to unapproved entities or diverted without valid orders, causing revenue misstatement.

E

Shipping module will not generate a packing list or gate pass unless tied to an approved, system-validated Sales Order.

P / A

Logistics Lead

Executed Bill of Lading matched to SO

REV-KC-03

Invoicing

Invoices issued for incorrect quantities or pricing, leading to top-line misstatement.

A,C

Three-Way Match (Sales): ERP automatically reconciles Sales Order pricing, Shipped Quantity (DO), and Billed Quantity. Deviations outside 0% trigger a hard system hold.

P / A

Revenue Accounting

ERP Automated System Match Report

REV-KC-04

Cash Recs

Cash collections misappropriated, applied incorrectly, or diverted (lapping fraud).

C,E

Daily automated bank statement download is reconciled against the AR ledger. Unapplied cash is reviewed weekly by the Treasury Controller.

D / SA

Treasury Accountant

Monthly Bank Rec Statement with CFO Sign-off

2. Procurement and Payment Cycle (Expenditure & Payables)

2.1 End-to-End Procedural Flow

  1. Purchase Requisition (PR): Raised by originating department with budget codes.

  2. Sourcing & Vendor Master Setup: Vendor onboarded via compliance background check; bank info locked in ERP.

  3. Purchase Order (PO): Dispatched to vendor following financial threshold matrix approval.

  4. Goods Receipt (GR): Receiving dock inspects physical condition and logs quantities against PO.

  5. Invoice Verification (AP): Invoice received digitally, matched via systematic checks.

  6. Payment Disbursement: Batch payment runs organized via treasury; dual token authorizations executed via corporate banking.

2.2 Process Flow Diagram

[PR Raised & Budget Check] ──> [Vendor Master Setup] ──> [PO Issued via Matrix]
                                                                  │
[Dual Token Bank Run] <── [Payment Voucher] <── [Three-Way Match] <── [GRN Logged]

2.3 Risk & Control Matrix (RCM)

Control ID

Process Step

Risk Description (What Could Go Wrong - WCGW)

Financial Assertion

Control Activity Description

Type / Mode

Owner

Evidence Artifact

PRC-KC-01

Vendor Master

Fictitious vendors created by internal staff to execute fraudulent payments.

E

Modification or creation of records in the Vendor Master File requires independent review by the Compliance Unit and dual-authorization workflow.

P / M

Master Data Team

Approved Vendor Onboarding Packet

PRC-KC-02

Order Processing

Purchasing commitments exceed approved corporate budgets, leading to unapproved expenditures.

A,P

ERP system validates funds availability against the cost-center budget before allowing PR-to-PO conversion.

P / A

Procurement Specialist

System Budget Availability Exception Report

PRC-KC-03

Processing

Payment generated for services or goods never delivered, or for incorrect rates.

E,A

Three-Way Match (Procurement): Payment vouchers cannot be processed unless a valid PO, verified Goods Receipt Note (GRN), and Supplier Invoice match.

P / A

Accounts Payable

System Verified Voucher Pack

PRC-KC-04

Disbursement

Unauthorized corporate fund outflows via malicious or incorrect bank transfers.

E

Electronic banking platform mandates dual-token authentication for all cash disbursements. Payments >$50,000 require CFO secondary approval.

P / SA

Treasury Director

Bank Settlement Log & Authorized Token Report

3. Financial Reporting Cycle (General Ledger & Closing)

3.1 End-to-End Procedural Flow

  1. Sub-ledger Close: AP, AR, Fixed Assets, and Payroll modules closed sequentially.

  2. Journal Entry Preparation: Non-routine, accrual, and consolidation adjustments drafted with worksheets.

  3. Review & Posting: Independent oversight checking allocation accuracy and accounting policies.

  4. Account Reconciliations: Balance sheet accounts substantiated via underlying dynamic evidence.

  5. Financial Consolidation: Eliminate intercompany transactions and convert currencies.

  6. Disclosure & Disclosure Review: Drafting final statements, footnotes, and regulatory forms.

3.2 Process Flow Diagram

[Sub-Ledger Freeze] ──> [Journal Preparation] ──> [Independent Review & Post]
                                                                │
[Executive / Board Review] <── [Consolidation & Adjustments] <── [Balance Sheet Substantiation]

3.3 Risk & Control Matrix (RCM)

Control ID

Process Step

Risk Description (What Could Go Wrong - WCGW)

Financial Assertion

Control Activity Description

Type / Mode

Owner

Evidence Artifact

FIN-KC-01

Journal Ledger

Management overrides controls via fraudulent manual journal entries to distort metrics.

E,A

Manual journals require Segregation of Duties: Creator cannot post. All entries >$10,000 require automated workflow routing to the Financial Controller.

P / A

Accounting Manager

System Audit Log of Manual JVs

FIN-KC-02

Reconciliations

Balance Sheet accounts contain undetected material variances or unresolved reconciling items.

A

All key balance sheet accounts are reconciled to sub-ledgers or external sources monthly. Reconciliations are reviewed and signed off by the GL Director within 15 business days of close.

D / M

GL Director

Signed Reconciliation Dashboard

FIN-KC-03

Consolidation

Intercompany transactions fail to eliminate, leading to inflated revenues and assets.

A,P

The ERP consolidation engine performs automated intercompany matching and elimination. A manual variance review is executed by the Group Reporting Team.

D / SA

Group Reporting Manager

System Intercompany Elimination Report

4. Investment Cycle (Treasury, M&A, & Securities)

4.1 End-to-End Procedural Flow

  1. Sourcing & Allocation: Corporate development identifies targets or treasury assesses cash-equivalent instruments.

  2. Financial Modeling & Due Diligence: Valuation stress-testing under dynamic assumptions (NPV, IRR).

  3. Governance Clearance: Formally presented to the Investment/Board Committee.

  4. Execution & Custody: Legal contracts signed; asset certificates registered or placed in secure institutional custody.

  5. Impairment & Fair-Value Revaluation: Regular monitoring of carrying costs against market indexes.

4.2 Process Flow Diagram

[Pipeline / Treasury Sourcing] ──> [Due Diligence & Valuations] ──> [Board Committee Approval]
                                                                            │
[Periodic Fair-Value Audit] <── [Asset Custody Controls] <── [Capital Wire & Settlement]

4.3 Risk & Control Matrix (RCM)

Control ID

Process Step

Risk Description (What Could Go Wrong - WCGW)

Financial Assertion

Control Activity Description

Type / Mode

Owner

Evidence Artifact

INV-KC-01

Governance

Company engages in high-risk, unauthorized investments, violating the board's risk appetite.

R,P

All investments exceeding $100,000 must align with the approved Corporate Investment Policy Statement (IPS) and receive written Board Investment Committee approval.

P / M

Board Secretary

Signed Board Minutes & Resolution

INV-KC-02

Custody

Securities or equity ownership certificates are lost, stolen, or misstated.

E

Independent physical/digital asset verification of certificates and portfolios is performed quarterly against external custodian statements.

D / M

Internal Audit

Custodian Confirmation Letters & Reconciliations

INV-KC-03

Revaluation

Changes in investment values are ignored, resulting in overstated asset values.

A

Semi-annual impairment assessments are performed for equity investments and long-term joint ventures. Valuation models use audited inputs or third-party reports.

D / M

CFO

Signed Impairment Review Memo

5. Financing Cycle (Debt & Equity Capital Operations)

5.1 End-to-End Procedural Flow

  1. Liquidity Planning: Long-range cash forecast identifies financing or equity raise requirements.

  2. Negotiation: Institutional bidding for loan facilities, bonds, or private placements.

  3. Statutory Approvals: Legal checks against maximum leverage ratios per bylaws.

  4. Drawdown Administration: Tracking principal execution, interest schedules, and monitoring loan covenants.

  5. Equity Cap Table Operations: Managing shares outstanding, option exercises, and dividend payments.

5.2 Process Flow Diagram

[Liquidity Forecast] ──> [Term Sheet Negotiation] ──> [Legal Matrix & Bylaw Validation]
                                                                  │
[Cap Table & Covenant Tracking] <── [Interest / Principal Run] <── [Fund Execution & Ledgering]

5.3 Risk & Control Matrix (RCM)

Control ID

Process Step

Risk Description (What Could Go Wrong - WCGW)

Financial Assertion

Control Activity Description

Type / Mode

Owner

Evidence Artifact

FIN-KC-04

Compliance

Debt covenants are breached, triggering immediate default and loan acceleration.

P,A

A Covenant Compliance Dashboard tracks leverage/liquidity metrics monthly. The General Counsel reviews this prior to signing the compliance certificate.

D / SA

Treasury Manager

Quarterly Signed Compliance Certificate

FIN-KC-05

Equity Registry

Share issuance occurs without proper authorization, resulting in equity dilution or regulatory fines.

E,R

Changes to the capitalization table (options, equity awards) must be authorized by the Board Compensation Committee and confirmed by an external transfer agent.

P / M

Corporate Secretary

Transfer Agent Registry Report

6. Construction Cycle (Capital Projects / CIP)

6.1 End-to-End Procedural Flow

  1. Project Initiation: Business case and formal Capital Expenditure (CAPEX) authorization requested.

  2. Engineering Tender: Competitive RFP issued to audited Engineering, Procurement, Construction (EPC) firms.

  3. Construction-In-Progress (CIP) Accounting: Ongoing project expenditures aggregated into designated CIP general ledger clearing accounts.

  4. Physical Progress Audit: On-site inspections evaluate milestone tracking before processing contractor billings.

  5. Capitalization Run: Asset components separated and moved to active Fixed Asset Registers upon operational handover.

6.2 Process Flow Diagram

[CAPEX Charter & Budget] ──> [EPC Firm Competitive RFP] ──> [CIP Cost Aggregation Ledger]
                                                                        │
[FAR Component Activation] <── [Handover Certificate] <── [Quantity Surveyor Progress Validation]

6.3 Risk & Control Matrix (RCM)

Control ID

Process Step

Risk Description (What Could Go Wrong - WCGW)

Financial Assertion

Control Activity Description

Type / Mode

Owner

Evidence Artifact

CON-KC-01

CAPEX Launch

Projects initiated without economic viability, leading to capital wastage.

E

Project charters require a documented NPV calculation and written sign-off from the CAPEX Review Committee prior to vendor commitments.

P / M

CAPEX Committee

Signed Project Charter & ROI Model

CON-KC-02

Progress Pay

Contractors bill for unearned milestones, causing overpayment and asset misstatement.

A

Milestone billings require an independent Quantity Surveyor's physical validation report and field project manager certification before invoice approval.

P / M

Project Director

Signed Progress Inspection Certificate

CON-KC-03

Capitalization

Finished assets remain in CIP accounts to defer depreciation, overstating net income.

P,A

Engineering provides formal Certificates of Substantial Completion monthly. Finance reconciles these to clear CIP accounts into the active Fixed Asset Register.

D / M

Fixed Asset Manager

Asset Capitalization Form (ACF)

7. Fixed Assets Cycle (Property, Plant, & Equipment)

7.1 End-to-End Procedural Flow

  1. Asset Activation: Barcode tagging and FAR profile configuration (useful life setting).

  2. Depreciation Calculation: Run monthly based on systematic parameters (Straight Line, Reducing Balance).

  3. Physical Verification: Tracking physical existence and conditions across geo-locations.

  4. Asset Disposal/Scrapping: Formal decommission workflows assessing salvage book values.

7.2 Process Flow Diagram

[FAR Configuration & Tagging] ──> [Systematic Depreciation Run]
                                             │
[Approved Asset Disposal] <── [Annual Physical Inventory Validation]

7.3 Risk & Control Matrix (RCM)

Control ID

Process Step

Risk Description (What Could Go Wrong - WCGW)

Financial Assertion

Control Activity Description

Type / Mode

Owner

Evidence Artifact

AST-KC-01

Asset Tracking

Fixed assets are stolen or misplaced without detection, overstating asset registers.

E

A wall-to-wall physical asset inventory is conducted annually by personnel independent of asset custody, reconciling items back to the FAR.

D / M

Internal Audit Lead

Reconciled Physical Inventory Report

AST-KC-02

Depreciation

Incorrect useful lives applied, resulting in misstated depreciation expenses and net book values.

A

Asset profiles are locked in the ERP by asset class. Modifications to configured useful lives require corporate accounting policy variance approval.

P / A

Fixed Asset Manager

ERP System Configuration Settings Log

AST-KC-03

Decommission

Assets are disposed of below book value without authorization or to favor internal staff.

E,A

Asset disposals require an approved Asset Disposal Form (ADF). Disposals of assets with net book values >$5,000 require CFO sign-off.

P / M

Operations VP

Executed ADF & Bill of Sale

8. HR and Payroll Cycle

8.1 End-to-End Procedural Flow

  1. Workforce Planning & New Hire Onboarding: Verified background screens, approved offer letters, and setting up core profiles in the HRIS (Workday/SAP SuccessFactors).

  2. Time & Attendance Management: Submitting and digitally approving project/shift hours.

  3. Payroll Calculation Engine: Running data aggregations (gross salary, social security withholdings, adjustments).

  4. Disbursement Authorization: Reconciling variances against payroll templates prior to bank transmission.

  5. Offboarding & Termination: Issuing final settlements, updating payroll registers, and revoking physical/logical system access.

8.2 Process Flow Diagram

[HRIS Setup & Compliance Check] ──> [Approved Time Sheets] ──> [Payroll Aggregation Run]
                                                                        │
[System Access Deactivation] <── [Final Settlement] <── [Variance Check & Disbursement]

8.3 Risk & Control Matrix (RCM)

Control ID

Process Step

Risk Description (What Could Go Wrong - WCGW)

Financial Assertion

Control Activity Description

Type / Mode

Owner

Evidence Artifact

PAY-KC-01

New Hire Onboarding

Ghost employees added to the HRIS, leading to unauthorized cash outlays.

E

Creating an employee profile in the HRIS requires an electronic workflow attached to a signed employment agreement and verified tax documentation.

P / A

HR Operations Director

Audit Trail of HRIS User Creation

PAY-KC-02

Payroll Review

Incorrect payroll calculations or unauthorized bonus adjustments occur undetected.

A

Before bank file transmission, a Corporate Payroll Variance Report compares current and prior month runs. Variances >3% per individual must be verified.

D / SA

Finance Director

Signed Monthly Payroll Variance Review

PAY-KC-03

Offboarding

Terminated employees continue to receive salary payments post-departure.

E,A

HR enters termination into the HRIS within 24 hours of separation. This automatically removes the employee profile from the upcoming active payroll run.

P / A

HR Systems Lead

Automated Termination Log vs Payroll Export

9. IT General Controls Cycle (ITGC Framework)

9.1 End-to-End Procedural Flow

  1. Logical Access Governance: Enforcing access controls through multi-factor authentication (MFA) and single sign-on (SSO).

  2. Change Management Administration: Structuring code/infrastructure changes via Sandbox → Staging → Production.

  3. IT Operations & Cyber Defense: Managing system monitoring, daily backups, and disaster recovery execution plans.

9.2 Process Flow Diagram

[Access Provisioning & RBAC] ──> [Sandbox Code Review] ──> [Staging Testing & Approval]
                                                                     │
[Disaster Recovery Drills] <── [Immutable Backup Runs] <── [Production Deployment Engine]

9.3 Risk & Control Matrix (RCM)

Control ID

Process Step

Risk Description (What Could Go Wrong - WCGW)

Financial Assertion

Control Activity Description

Type / Mode

Owner

Evidence Artifact

ITG-KC-01

Access Control

Excessive system privileges lead to unauthorized data modifications or Segregation of Duties violations.

All Assertions

Privilege management follows Role-Based Access Control (RBAC). Access rights are reviewed quarterly by department heads to confirm access remains appropriate.

D / M

IT Security Manager

Quarterly User Access Review Sign-offs

ITG-KC-02

Change Management

Unapproved or untested code updates disrupt ERP financial processing logic.

A

Changes to production environments require a documented ticket detailing testing in a staging environment and explicit Change Advisory Board (CAB) approval.

P / SA

Change Management Chair

Closed CAB Deployment Ticket

ITG-KC-03

Operations

Ransomware or system failures lead to data loss or unrecoverable financial ledgers.

C,A

Automated full backups are performed daily and stored in an immutable, off-site cloud environment. Recovery tests are completed and documented semi-annually.

P / A

Infrastructure Director

Semi-Annual Backup Restoration Test Log

SECTION III: APPENDIX – PROFESSIONAL TEMPLATES & FORMS

To build out the auxiliary sections of the manual, use the standardized operating blueprints below.

1. Template: Credit Evaluation and Limit Approval Form

FORM CODE: FIN-CR-001A
================================================================================
CUSTOMER IDENTIFICATION
Customer Name: ________________________  Registration No: _____________________
Country of Incorporation: _____________  Tax Identification ID: ______________

FINANCIAL METRICS ASSESSMENT (FY-2026/LTM)
Annual Revenue: $_____________________  Net Current Assets: $__________________
Leverage Ratio (Debt/Equity): ________  Altman Z-Score Calculation: __________

PROPOSED CREDIT TERMS
Requested Limit: $____________________  Requested Payment Window: ______ Days
Internal Credit Rating Assigned: [ ] Low Risk  [ ] Medium Risk  [ ] High Risk

APPROVAL WORKFLOW
Credit Risk Analyst Signature: _______________________ Date: 2026-__-__
Credit Director Approval (> $50k): _____________________ Date: 2026-__-__
CFO Secondary Validation (> $250k): __________________ Date: 2026-__-__
================================================================================

2. Template: Capital Expenditure (CAPEX) Project Charter Form

FORM CODE: CPX-PC-007B
================================================================================
PROJECT OVERVIEW
Project Title: _________________________________________________________________
Originating Asset/Site Location: _______________________ Cost Center: _________
Target Operational Date: 2026-__-__

FINANCIAL FEASIBILITY ANALYSIS (Attach Detailed Spreadsheet)
Total Estimated Capital Budget: $_______________________
Expected Payback Period: ______________ Months
Calculated Net Present Value (NPV): $__________________ (Discount Rate Used: __%)
Internal Rate of Return (IRR): ________%

COMPLIANCE STRATEGY & TESTING MANDATES
Does this procurement interface with automated financial reporting tools? [Yes/No]
List corresponding control IDs managed by this asset deployment: _____________

MANAGEMENT AUTHORIZATION
Department VP Authorization: _________________________ Date: 2026-__-__
CAPEX Committee Validation: __________________________ Date: 2026-__-__
Executive Board Resolution ID (If >$1M): _______________ Date: 2026-__-__
================================================================================

3. Template: Access Provisioning & Segregation of Duties (SoD) Clearance Form

FORM CODE: IT-SOD-003C
================================================================================
USER IDENTIFICATION & SYSTEM PROFILE
Full Legal Employee Name: ___________________________ Employee ID: ___________
Department: _________________________________________ Job Title: ______________
Target Enterprise System: [ ] SAP S/4HANA  [ ] Oracle Cloud  [ ] Workday  [ ] Other

REQUESTED SYSTEM PROFILES/ROLES
Role Code 1: ________________________  Description: ___________________________
Role Code 2: ________________________  Description: ___________________________

SEGREGATION OF DUTIES (SOD) CONFLICT VERIFICATION MATRIX
Check potential conflict pairs:
[ ] AP Voucher Creation + Bank Payment File Generation [CONFLICT DETECTED]
[ ] Customer Master Setup + Sales Invoice Issuance      [CONFLICT DETECTED]
[ ] Journal Voucher Creation + General Ledger Posting  [CONFLICT DETECTED]

Risk Assessment Findings:
[ ] Zero conflicting matrices identified under requested application profiles.
[ ] Conflict detected. Compensating Control Matrix ID linked: _________________

SIGN-OFF CLEARANCE
Requesting Manager Signature: ________________________ Date: 2026-__-__
Risk & Compliance Auditor Validation: ________________ Date: 2026-__-__
CIO Infrastructure Authorization: ____________________ Date: 2026-__-__
================================================================================

SECTION IV: EXECUTION GUIDELINES FOR THE 400+ PAGE VOLUME

To scale this foundational blueprint to a comprehensive manual for organizational rollout:

  1. Populate Business Unit Variances: Expand the sub-ledger sections to document specific workflows for local operating models (e.g., subscription billings vs. physical product inventory lines).

  2. Incorporate Detailed System Walkthroughs: Embed step-by-step transaction pathways into the procedures (e.g., detailing exactly which transaction codes or system menus to use when running a three-way match report or executing a bank run).

  3. Expand Risk Scenarios: Build out the Risk and Control Matrix to cover edge cases, such as handling split-shipments or mid-month contract amendments, ensuring each scenario is mapped to a documented control activity and testing procedure.


Resources: Internet

Comments


bottom of page